Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: TRACE used to increase the dangerous of XSS.

From: Richard M. Smith <rms(at)computerbytesman.com>
Date: Wed Jan 22 2003 - 17:34:59 EST


Isn't this a bug in Internet Explorer? Shouldn't the Microsoft XMLHTTP ActiveX control be removing cookies from returned HTTP headers when a HTTP TRACE is done? I know that this already happens when a GET or a POST is done with XMLHTTP.

Richard M. Smith
http://www.ComputerBytesMan.com

-----Original Message-----
From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com] Sent: Wednesday, January 22, 2003 3:33 PM To: bugtraq@securityfocus.com; webappsec@securityfocus.com; vulnwatch@vulnwatch.org
Subject: TRACE used to increase the dangerous of XSS.

WhiteHat Security has released a new white paper discussing a new class of web-app-sec attack (XST) which potentially affects all web servers supporting TRACE.

The white paper explains all the detailed technical results we have found so far. We are fairly certain this particular issue will spark much debate and encourage those interested to read and comment.

White Paper Mirrors:

http://www.betanews.com/whitehat/WH-WhitePaper_XST_ebook.pdfhttp://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdfhttp://www.boarder.org/WH-WhitePaper_XST_ebook.pdfhttp://www.forumgalaxy.com/whmirror/WhitePaper_screen.pdf

Press Release
http://www.whitehatsec.com/press_releases/WH-PR-20030120.txt Received on Wed Jan 22 18:21:13 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:47 EDT

Do you need help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library